6.8

CVE-2014-1901

Y-Cam camera models SD range YCB003, YCK003, and YCW003; S range YCB004, YCK004, YCW004; EyeBall YCEB03; Bullet VGA YCBL03 and YCBLB3; Bullet HD 720 YCBLHD5; Y-cam Classic Range YCB002, YCK002, and YCW003; and Y-cam Original Range YCB001, YCW001, running firmware 4.30 and earlier, allow remote authenticated users to cause a denial of service (reboot) via a malformed (1) path parameter to en/store_main.asp, (2) item parameter to en/account/accedit.asp, or (3) emailid parameter to en/smtpclient.asp.  NOTE: this issue can be exploited without authentication by leveraging CVE-2014-1900.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Y-camYceb03 Firmware Version4.30
   Y-camYceb03
Y-camYcb004 Firmware Version4.30
   Y-camYcb004
Y-camYcb002 Firmware Version4.30
   Y-camYcb002
Y-camYcbl03 Firmware Version4.30
Y-camYcblb3 Firmware Version4.30
Y-camYck002 Firmware Version4.30
   Y-camYck002
Y-camYcblhd5 Firmware Version4.30
   Y-camYcblhd5
Y-camYcw003 Firmware Version4.30
   Y-camYcw003
Y-camYcw001 Firmware Version4.30
   Y-camYcw001
Y-camYcw002 Firmware Version4.30
   Y-camYcw002
Y-camYcb001 Firmware Version4.30
   Y-camYcb001
Y-camYcw004 Firmware Version4.30
Y-camYck003 Firmware Version4.30
   Y-camYck003
Y-camYck004 Firmware Version4.30
   Y-camYck004
Y-camYcb003 Firmware Version4.30
   Y-camYcb003
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.62% 0.676
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.8 8 6.9
AV:N/AC:L/Au:S/C:N/I:N/A:C
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.